ISO/IEC 42001 vs NIST AI RMFAI governance comparisonISO/IEC 42001
ISO/IEC 42001 ISO/IEC 42001 vs NIST AI RMF
ISO/IEC 42001 specifies certifiable AIMS requirements; the NIST AI Risk Management Framework is voluntary, rights-preserving, non-sector-specific guidance organised around GOVERN, MAP, MEASURE, and MANAGE.
NIST AI RMF practices can strengthen AIMS risk work. A profile or Playbook selection does not by itself satisfy ISO/IEC 42001's management-system, documented-information, impact-assessment, internal-audit, management-review, and corrective-action requirements.
Use one governance programme if helpful, but preserve the source mapping. ISO/IEC 42001:2023 supports a conformity claim against a defined AIMS scope. supports voluntary risk management and profiles; it is not an ISO certification standard, a mandatory checklist, or a legal compliance route. NIST states that AI RMF 1.0 is being revised, so record the version used in every crosswalk.
ISO/IEC 42001 vs NIST AI RMF comparison
ISO/IEC 42001 vs NIST AI RMF: scope, duties, evidence, and decision rule
This side-by-side comparison helps teams decide when ISO/IEC 42001 is the primary framework, when NIST AI RMF is the governing analysis source, and how to sequence evidence cleanly.
Auditable requirements for an organisation-wide AIMS, including policy, risk and impact processes, controls, evaluation, internal audit, management review, and improvement.
Second framework
NIST AI RMF
Voluntary AI risk-management framework using GOVERN, MAP, MEASURE, and MANAGE functions, supported by profiles and a non-prescriptive playbook.
ISO/IEC 42001 vs NIST AI RMF: scope, duties, evidence, and decision rule
is a voluntary, rights-preserving, non-sector-specific, use-case-agnostic framework for managing risks to individuals, organisations, society, and the environment across the AI lifecycle.
Define the AIMS boundary and NIST profile or use-case boundary separately. Record the AI RMF version because NIST states that version 1.0 is being revised.
ISO/IEC 42001 ownership should sit with the team that can operate the relevant management system, control process, risk method, supplier relationship, incident process, privacy process, or AI governance scope.
NIST AI RMF distributes responsibilities across AI actors and lifecycle functions; organisations tailor ownership to context, risk, resources, and their profile rather than a certification boundary.
ISO/IEC 42001 work is triggered by scope definition, implementation, certification readiness, customer assurance, control gaps, incidents, supplier changes, or management review.
NIST AI RMF is adopted voluntarily when an organisation wants to govern, map, measure, and manage AI risks or create a current and target profile for a use case or programme.
Decide whether the record is an AIMS conformity requirement, a NIST profile choice, or both. Then retain the relevant ISO clause and NIST function or subcategory instead of labeling the work generically as AI governance.
The Core organises outcomes into GOVERN, MAP, MEASURE, and MANAGE. GOVERN is cross-cutting; categories and subcategories describe outcomes and actions, not a mandatory checklist or fixed sequence.
Cross-map NIST outcomes to the AIMS only where purpose and evidence align. Mark partial coverage, uncovered ISO requirements, and unaddressed profile outcomes.
ISO/IEC 42001 evidence should show the process operating: owners, decisions, registers, control records, test results, review minutes, audit samples, or corrective actions.
Evidence can include current and target profiles, contextual mappings, risk measurements, prioritisation and treatment decisions, governance assignments, monitoring results, and documented trade-offs.
ISO/IEC 42001 timing follows implementation, audit, certification, review, supplier, incident, or change cycles rather than a single universal deadline.
NIST AI RMF has no universal compliance deadline. Cadence follows the organisation's AI lifecycle, profile, risk context, monitoring, and change triggers.
ISO/IEC 42001 is usually tested through certification audits, internal audits, customer assurance, management review, or governance review, depending on how the organization adopts it.
is a voluntary, rights-preserving, non-sector-specific, use-case-agnostic framework for managing risks to individuals, organisations, society, and the environment across the AI lifecycle.
Define the AIMS boundary and NIST profile or use-case boundary separately. Record the AI RMF version because NIST states that version 1.0 is being revised.
ISO/IEC 42001 ownership should sit with the team that can operate the relevant management system, control process, risk method, supplier relationship, incident process, privacy process, or AI governance scope.
NIST AI RMF distributes responsibilities across AI actors and lifecycle functions; organisations tailor ownership to context, risk, resources, and their profile rather than a certification boundary.
ISO/IEC 42001 work is triggered by scope definition, implementation, certification readiness, customer assurance, control gaps, incidents, supplier changes, or management review.
NIST AI RMF is adopted voluntarily when an organisation wants to govern, map, measure, and manage AI risks or create a current and target profile for a use case or programme.
Decide whether the record is an AIMS conformity requirement, a NIST profile choice, or both. Then retain the relevant ISO clause and NIST function or subcategory instead of labeling the work generically as AI governance.
The Core organises outcomes into GOVERN, MAP, MEASURE, and MANAGE. GOVERN is cross-cutting; categories and subcategories describe outcomes and actions, not a mandatory checklist or fixed sequence.
Cross-map NIST outcomes to the AIMS only where purpose and evidence align. Mark partial coverage, uncovered ISO requirements, and unaddressed profile outcomes.
ISO/IEC 42001 evidence should show the process operating: owners, decisions, registers, control records, test results, review minutes, audit samples, or corrective actions.
Evidence can include current and target profiles, contextual mappings, risk measurements, prioritisation and treatment decisions, governance assignments, monitoring results, and documented trade-offs.
ISO/IEC 42001 timing follows implementation, audit, certification, review, supplier, incident, or change cycles rather than a single universal deadline.
NIST AI RMF has no universal compliance deadline. Cadence follows the organisation's AI lifecycle, profile, risk context, monitoring, and change triggers.
ISO/IEC 42001 is usually tested through certification audits, internal audits, customer assurance, management review, or governance review, depending on how the organization adopts it.
Use ISO/IEC 42001:2023 as the lead framework when the objective is to establish, operate, assess, or certify an artificial intelligence management system (AIMS). Its requirements cover organisational context, scope, leadership, policy, roles, risk and impact processes, support, operation, performance evaluation, internal audit, management review, and improvement.
Use when the objective is a voluntary, flexible way to govern, map, measure, and manage AI risk across the lifecycle. The Core contains functions, categories, and subcategories; its actions and outcomes are not a checklist or a mandatory ordered sequence. NIST frames trustworthy AI characteristics as valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed, while recognising trade-offs between them.
Use both when an AIMS needs a detailed risk vocabulary, current and target profiles, or NIST outcome mapping. Crosswalk at the outcome and evidence level. Similar wording does not make an ISO requirement and a NIST subcategory equivalent.
Choose ISO/IEC 42001 for an AIMS conformity or certification objective.
Choose for voluntary risk outcomes, profiles, and a common vocabulary that can be tailored to the use case.
Use the NIST Generative AI Profile when generative-AI-specific risks and actions are relevant, but keep it identified as a profile of AI RMF 1.0 rather than a replacement for the Core or ISO/IEC 42001.
What evidence should the combined programme produce?
For ISO/IEC 42001, retain the documented AIMS scope, policy and objectives, role assignments, risk criteria, assessments, treatment plans, statement of applicability, impact assessments, operating controls, monitoring results, internal audits, management reviews, and corrective actions.
For NIST AI RMF, retain the chosen profile or outcome set, context mapped under MAP, measurement methods and results under MEASURE, prioritisation and response decisions under MANAGE, and the policies, roles, accountability, culture, and oversight established under GOVERN. A current profile records outcomes already achieved; a target profile records outcomes the organisation plans to achieve for the defined use case or programme. The gap can guide priorities, but the profile is not a conformity certificate.
One record can support both frameworks when the scope, system version, actors, risk question, acceptance criteria, and review status align. The crosswalk should identify partial coverage and gaps rather than force one-to-one matches.
Scope record: AIMS boundary, NIST profile boundary, AI system and lifecycle stage, intended purpose, users, affected people, deployment context, and external requirements.
Outcome map: exact ISO clause or control and exact NIST function, category, or subcategory, with the reason for the mapping and any uncovered requirement.
Operation record: risk and impact assessments, test methods and results, monitoring, incident and feedback records, treatment decisions, control evidence, approvals, and residual-risk decisions.
Version record: ISO/IEC 42001 edition, AI RMF version, profile or Playbook version, crosswalk date, owner, assumptions, and reassessment trigger.
Start with a defined use case and AIMS boundary. Identify lifecycle actors, intended purpose, affected people, deployment context, external requirements, and the risks to people, organisations, society, and the environment. Select the NIST outcomes that fit that context and create a current or target profile when that helps prioritisation. Then map each selected outcome to ISO/IEC 42001 only where the purpose and expected evidence align.
GOVERN is cross-cutting and informs the other NIST functions. After governance outcomes are in place, teams commonly use MAP to establish context, MEASURE to analyse and evaluate risk, and MANAGE to prioritise and respond. NIST does not require teams to implement every Playbook suggestion or follow the Playbook as an ordered checklist.
1. Define the AIMS scope, AI system or use-case boundary, lifecycle stage, actors, affected parties, and external requirements.
2. Select and document the relevant NIST Core outcomes or profile; do not assume every subcategory applies.
3. Map ISO/IEC 42001 clauses and Annex A controls to NIST outcomes with full, partial, or no coverage.
4. Assign owners and collect evidence through the operating process, not through the crosswalk itself.
5. Review gaps against ISO conformity requirements and NIST target-profile priorities separately.
6. Reassess after material model, data, purpose, deployment, supplier, incident, measurement, legal, or framework-version changes.
Do not treat a NIST profile, Playbook selection, or completed crosswalk as proof of ISO/IEC 42001 conformity. Similar governance and risk outcomes can share evidence, but ISO requirements and NIST outcomes still need separate completeness tests.
Do not call NIST AI RMF a certification scheme, a law, or a mandatory checklist. NIST describes it as voluntary and tailorable. The Playbook supplies suggested actions, and organisations may use as many or as few as fit their use case.
Do not freeze the mapping. NIST states that AI RMF 1.0 is being revised, and companion resources can change. Keep the exact framework, profile, Playbook, and crosswalk versions with the evidence.
Do not cite a standard title as evidence that a process is operating.
Do not reuse an old audit artifact after the scope, service, supplier, or risk has changed.
Do not hide exceptions; record them as risk acceptance, corrective action, or management-review inputs.
Review the AIMS through its planned monitoring, internal-audit, management-review, and improvement processes. Review the NIST profile and outcome priorities when context, measurements, risks, resources, or stakeholder needs change.
A framework revision is also a trigger. As of 25 July 2026, NIST identifies AI RMF 1.0 as under revision and says the Playbook will be updated after that revision. When a new version is adopted, assess changed outcomes, profiles, Playbook suggestions, and mappings before reusing old conclusions.
Set separate review dates for the AIMS, the NIST profile, and the crosswalk.
Track framework and profile versions alongside system, model, data, and supplier versions.
Update owners, evidence links, gap status, risk decisions, and corrective actions when a mapping or operating conclusion changes.
NIST explains that the Playbook contains suggested actions for the four functions and that organisations may use as many or as few suggestions as apply.